Generative AI in Cybersecurity: Assessing impact on current and future malicious software
This CETaS Briefing Paper explores the potential of generative artificial intelligence (GenAI) in creating malicious software and is aimed at informing risk management and supporting the AI-cybersecurity evaluation community. The cybersecurity field is divided, with some fearing GenAI could lead to novel threats while others believe it merely automates existing malicious code. Despite the release of GPT-4 in March 2023 there has been no noticeable increase in novel malware detected. GenAI currently lacks the capabilities to independently create operational malware and autonomously identify and exploit vulnerabilities, but its future impact on cybersecurity could be profound, especially as models and datasets improve, leading to potential scenarios where AI-created malware and AI-based defence systems continuously evolve. Effective use of GenAI in cybersecurity requires leveraging its strengths in pattern recognition and natural language processing, and fostering collaboration between AI and cybersecurity communities to ensure cyber defence stays ahead of the AI-enabled game.